ChainThink reports that on August 8, BTCPay Server announced on X that its Bitcoin payment processing platform has identified a critical vulnerability currently under active attack, which could allow attackers to gain unauthorized access and result in fund losses.
The official requirement is for administrators to upgrade to version 2.4.2 and confirm that the server footer displays the update as complete; if an immediate upgrade is not possible, it is recommended to temporarily shut down BTCPay Server to prevent further attacks.
BTCPay Server also recommends that users rotate potentially exposed macaroon credentials, recreate the macaroons.db file, and refresh authentication strings for other Lightning Network backends.
If a user creates a hot wallet in BTCPay Server, the official recommendation is to transfer the funds and recreate the wallet.
At this time, BTCPay Server has not disclosed the specific details of the vulnerability, the start time of the attack, the number of affected servers, or whether any funds have been stolen. The vulnerability was reported by a member of the Bitcoin Red Team.

